Optus and Medibank face separate legal proceedings over their 2022 data breaches. Australia’s privacy regulator alleges that each company failed to take reasonable steps to protect personal information; Optus also faces a separate telecommunications-regulator case, while customers and Medibank shareholders have brought private claims. These are allegations, not final findings of liability.
Procedural status checked against the Federal Court listings and other cited material available on August 18, 2026. Court listings and orders can change.
What the cases allege—and what they do not establish
The central legal question is not simply whether criminals attacked the companies. It is whether the companies’ security controls and risk management were reasonable in context, given the information they held and the risks they faced. The Australian Information Commissioner (OAIC) has brought separate Federal Court civil-penalty proceedings concerning Optus and Medibank. Neither proceeding, by itself, establishes that the allegations are true or that affected customers are entitled to a particular payment.
- Established event: Optus disclosed a cyberattack in September 2022; Medibank and its ahm subsidiary experienced a cyberattack in October 2022.
- Regulatory allegations: The OAIC alleges shortcomings in each company’s protection of personal information. The Australian Communications and Media Authority (ACMA) separately alleges Optus failed to meet telecommunications confidentiality obligations.
- Unresolved claims: Customer and shareholder proceedings raise separate questions about liability, loss, causation, and any remedy. A filing or regulator announcement is not a court finding.
What is alleged in the Optus proceedings?
The 2022 breach and OAIC case
Optus made the attack public on September 22, 2022. The OAIC filed civil-penalty proceedings against Singtel Optus Pty Limited and Optus Systems Pty Limited in 2025. The regulator alleges that Optus did not adequately manage cybersecurity and information-security risks in proportion to the nature and volume of information it held, the organization’s size and resources, and its risk profile. The OAIC’s case concerns the company’s risk-management arrangements, not merely the fact that an attacker gained access. OAIC: Optus civil-penalty action
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
ACMA’s separate telecommunications case
ACMA’s proceeding addresses a different legal duty. It alleges that, between September 17 and September 20, 2022, Optus failed to protect the confidentiality of customers’ personal information from unauthorised interference or access as required by the Telecommunications (Interception and Access) Act 1979 (Cth). This is distinct from the OAIC’s privacy-law case: the regulators, statutes, and questions are not interchangeable. ACMA statement on the Optus breach
Optus customer class action and report dispute
The Federal Court lists Peter Julian Robertson & Anor v Singtel Optus Pty Limited as a current class action, with Justice Beach assigned. The private case may address whether Optus breached obligations and whether group members can establish compensable loss; those issues remain for the proceeding, rather than being resolved by the OAIC or ACMA filings. Federal Court: current class actions
There has also been litigation about access to an internal Deloitte report concerning the breach. The Federal Court material includes Robertson v Singtel Optus Pty Ltd [2023] FCA 1392 and the Full Court decision Singtel Optus Pty Ltd v Robertson [2024] FCAFC 58. That procedural dispute about a report is not proof that the report established liability. Federal Court judgment material
What is alleged in the Medibank proceedings?
The 2022 breach and OAIC case
Medibank notified the OAIC of the breach on October 25, 2022, after detecting the incident. The incident involved personal and health-related information, making the sensitivity of the records a central feature of the case. On June 5, 2024, the OAIC commenced Federal Court civil-penalty proceedings against Medibank Private Limited. It alleges Medibank failed to take reasonable steps to protect personal information, considering its size and resources, the nature and volume of the data, its sensitivity, and the risk of serious harm to individuals. OAIC: Medibank civil-penalty action
Reporting on the regulator’s court documents describes allegations involving the absence of multifactor authentication (MFA) for relevant access and weaknesses around credentials and contractor access. Those are allegations about particular systems and circumstances, not a final finding that Medibank breached the law. ABC News: reported MFA allegations
Customer class action and OAIC representative complaint
The Federal Court lists Zoe Lee McClure v Medibank Private Limited as a current class action. The OAIC also has a representative complaint process, but it expressly distinguishes that process from the Federal Court case. A regulator complaint and a class action have different procedures and potential outcomes; making one does not automatically make someone a member of the other. Federal Court class-action list · OAIC: Medibank representative complaint notice
Rank #3
Separate shareholder proceeding
The Supreme Court of Victoria lists a Medibank group proceeding for people who acquired an interest in Medibank shares between July 1, 2019 and October 25, 2022. It alleges, among other things, misleading or deceptive conduct and breaches of continuous-disclosure obligations concerning alleged cybersecurity deficiencies. This is an investor-loss case, not a customer privacy claim: it concerns whether alleged nondisclosure affected investors and their losses. The allegations are unresolved. Supreme Court of Victoria: Medibank group proceeding
In a company disclosure dated February 19, 2026, Medibank said mediation in the shareholder litigation was to be completed by September 2026. A stated mediation timetable is not evidence that a settlement has been reached or approved. Medibank company disclosure
How the proceedings differ
| Proceeding | Who brings it | Main issue | What it is not |
|---|---|---|---|
| OAIC civil-penalty case against Optus | Australian Information Commissioner | Alleged inadequate cybersecurity and information-security risk management under the privacy framework | A direct damages claim paying customers automatically |
| ACMA case against Optus | Australian Communications and Media Authority | Alleged failure to protect customer-information confidentiality under telecommunications legislation | The OAIC’s privacy proceeding |
| Optus customer class action | Applicants representing group members | Alleged obligations, causation, loss, and potential relief for customers | A regulator-imposed civil penalty |
| OAIC civil-penalty case against Medibank | Australian Information Commissioner | Alleged failure to take reasonable steps to protect personal information | A guaranteed per-customer compensation scheme |
| Medibank customer class action | Applicants representing group members | Customer claims and potential remedies arising from the breach | The OAIC representative complaint or the shareholder case |
| Medibank shareholder proceeding | Investors in a group proceeding | Alleged disclosure failures and investor loss | A claim that every affected customer incurred the same loss |
Regulatory civil penalties are distinct from private compensation. Depending on the legal basis and outcome, a regulator proceeding may result in penalties or other court orders; it does not necessarily direct equal payments to all people whose information was held. Private claims require their own legal and evidentiary assessment. The Supreme Court of Victoria’s description of the shareholder case illustrates why investor loss should not be conflated with customer harm. Supreme Court of Victoria: proceeding details
Rank #4
What the cybersecurity allegations mean in practice
Identity controls, MFA, and credentials
MFA adds a verification step beyond a password and can reduce the risk that stolen credentials alone will open an account. It is not a complete defence: attackers may steal session tokens, exploit malware or social engineering, or misuse privileged access. The legal question in these cases is not whether MFA is mandatory in every system; it is whether the security steps taken were reasonable for the access, threat, and sensitivity involved. The reported Medibank MFA and credential claims remain allegations in court material. ABC News report on the allegations
Contractor access and least privilege
Organizations commonly rely on contractors and service providers, but delegation does not remove the need to manage access risk. Relevant questions include whether accounts were limited to necessary systems, credentials were stored securely, access was monitored, and accounts were removed when no longer needed. A contractor’s involvement does not by itself establish a company’s legal liability; the adequacy of governance and controls is part of what must be assessed.
Monitoring, segmentation, and data movement
Logging, alerts for unusual access or downloads, privileged-account monitoring, network segmentation, endpoint protection, and tested escalation plans can help detect or limit an intrusion. Their absence or weakness matters legally only in context and as supported by evidence; the breach alone does not establish which controls failed or whether any failure was unreasonable.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Retention and governance
Holding less unnecessary information can reduce the material exposed in a breach, but deletion is not a one-size-fits-all answer. Organizations must distinguish records needed to provide a service or meet legal obligations from records kept through inertia, then apply retention schedules and secure deletion. The OAIC’s allegations against both companies emphasize security and risk management relative to the scale and sensitivity of the information held. OAIC: Optus allegations · OAIC: Medibank allegations
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected customers can do
Being notified by a company, falling within a class definition, registering interest with a law firm, and making an OAIC complaint are not the same thing. Follow official court notices and approved instructions for membership, opting out, deadlines, and any settlement process; do not assume a law-firm registration page determines eligibility. The Federal Court says case-progress information can include orders, filed documents, judgments, and future listings. Federal Court: check case progress
- Keep breach notifications and correspondence. Record identity-theft attempts, fraud, replacement-document costs, and time spent addressing misuse.
- Use unique passwords, enable MFA on email, banking, government, and other important accounts, and monitor account alerts.
- Be cautious of messages using a breach or lawsuit as a pretext. Verify any legal service, fees, and authority independently; do not pay an unverified registration service.
- Seek Australian legal advice for an individual claim or urgent identity-fraud issue. These proceedings do not guarantee recovery for every affected person.
Readers can monitor court activity through the Federal Court case-progress service and Commonwealth Courts Portal case tracking. Federal Court: track a case
What Australian businesses should take from the cases
These proceedings do not establish a universal checklist or a rule that any single control, including MFA, is always legally required. They do underline the importance of being able to show that security measures fit the organization’s data, scale, and risk. Practical governance includes:
- requiring strong authentication for remote and privileged access, with exceptions documented and monitored;
- reviewing contractor accounts, permissions, credentials, and offboarding;
- testing logging, unusual-download alerts, segmentation, and incident escalation rather than assuming they work;
- setting defensible retention and deletion schedules for identity and sensitive records;
- conducting independent security testing and exercises, and tracking remediation to completion; and
- reporting material cyber risks to senior management and boards in a way that supports informed oversight.
Current status and how to verify it
As of August 18, 2026, the Federal Court lists both the Robertson Optus and McClure Medibank customer proceedings as current matters; its public-interest page also identifies McClure v Medibank Private as an open class action. Medibank’s shareholder proceeding is separately listed by the Supreme Court of Victoria. These listings establish that the matters are on the courts’ lists, not that the allegations have been proved or a settlement approved. Federal Court class actions · Federal Court cases of public interest · Supreme Court of Victoria
To check the latest orders, hearing dates, or judgments, use the court’s case-progress and tracking services rather than relying on older news reports. Check Federal Court case progress · Track a case through the Commonwealth Courts Portal
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




